Written for this product; Common Paper does not provide one

Privacy Policy

In effect from 2026-09-24.

Data Cartel Cloud is run by PRIORA, LLC. This policy covers the product at datacartel.io and this website. It was written from what the software actually does, and it changes when the software does.

Two different roles

For everything a customer puts into their portal, we act on that customer's instructions and they decide what is collected and why. If you are a member of a customer's workspace, ask that organization about its own privacy notice. Our Data Processing Agreement sets out what we may do with that data.

For our own customer accounts, billing and this website, we decide, and this policy applies directly.

What the product holds

Account details for each person who signs in: email address, name and avatar link, and which organization and business units they belong to.

Whatever customers write in their portal: roadmaps, changelogs, documents, updates, health checks, metrics and logistics contacts. Free text can name people, and contacts hold a name, an email address and a role.

Billing contact details, held by Stripe: the email address of the person who subscribed. Card details are entered on Stripe's own pages and never reach us.

Security records: sign-in events with the email address masked to its first two characters, every support session with the reason and time, every data export with who ran it, and every change made through the automation server.

We store no uploaded files. A Word document is turned into text as it is read, and only the text is kept. There is no analytics service, no error tracking service and no advertising anywhere in the product. Fonts are served from our own servers.

What this website holds

If you join the waitlist, your email address is sent to a mailbox we read. It is not added to a marketing list and it is not stored in a database.

The website sets no analytics or advertising cookies. The product sets two cookies, both necessary: one that keeps you signed in, and one that protects the sign-in form against forged requests.

Why we hold it

To provide the service the customer is paying for, which is the contract between us.

To take payment, and to keep the billing records tax law requires.

To keep the service secure and to investigate abuse, which is our legitimate interest, balanced by logging as little as possible: no portal content is ever written to a log.

Who else handles it

Four companies, all in the United States, listed with what each one does at datacartel.io/subprocessors: Vercel for hosting, Neon for the database, Resend for email and Stripe for payments.

We give customers at least 10 business days' notice before that list changes, and 30 days to object.

We do not sell personal data, we do not share it for advertising, and we do not use customer content to train machine learning models.

Where it goes

Everything is stored and processed in the United States. For customers in the European Economic Area and the United Kingdom, our Data Processing Agreement includes the European Commission's Standard Contractual Clauses and the UK Addendum, with Ireland as the governing member state.

How long we keep it

Portal data stays while the organization has an account. An owner can delete the organization at any time, which starts a 30-day grace period and then removes every record it holds. All that survives is the workspace address, kept so it can never be handed to another company, with the dates of the request and the deletion.

Removing a person removes their account if they belong to nowhere else. Their name can remain inside content that mentions them, and the record that they once exported data keeps their email address, so that removing someone does not erase what they took.

Sign-in links last 60 minutes, work once, and are stored only as a hash.

Copies persist in the database's point-in-time history for six hours after deletion, and Stripe keeps its own billing records for as long as the law requires.

Your rights

You can ask for a copy of your personal data, ask us to correct or delete it, or object to how we use it. If your data is in a customer's workspace, ask that organization first: they control it, and we help them answer.

Write to us at the address below. We answer within 30 days. If you are in the European Economic Area or the United Kingdom, you can also complain to your data protection authority, which for our European customers is Ireland's Data Protection Commission.

Security, and children

How the service is protected, including what is not in place yet, is written out at datacartel.io/security.

Data Cartel is a workplace tool. It is not meant for children, and we do not knowingly collect their data.

Changes, and how to reach us

When this policy changes we post the new version here with its date. If a change materially affects customers, we email the owners of each organization.

Privacy questions: legal@datacartel.io. Security reports: security@datacartel.io.

By post: PRIORA, LLC, P.O. Box 1469, Grantham, NH 03753, United States.

Questions: hello@datacartel.io.